Attackers widely exploited CVE-2023-4966 (Citrix Bleed), a critical flaw in NetScaler ADC and NetScaler Gateway that can leak sensitive information, including session authentication tokens, and enable authentication bypass or session hijacking on affected Gateway or AAA virtual servers. Citrix issued a critical security update and later published investigation recommendations, while defenders reported attack activity beginning in late October and rising sharply through November. One observed technique targeted /oauth/idp/.well-known/openid-configuration with an unusually long Host header to steal session cookies, and a large share of detected attack traffic was traced to infrastructure in Germany, followed by Russia, China, Japan, and the United States.
The vulnerability was later tied to real-world intrusions, including a PLAY ransomware compromise of a professional services firm. After obtaining access through Citrix Bleed, the attackers performed internal reconnaissance to enumerate domain accounts, trusted domains, permission groups, and remote systems before advancing their operation. Security guidance urged organizations running affected NetScaler products, including unsupported 12.1 versions, to apply fixed releases immediately and investigate for signs of token theft or unauthorized session use.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
CISA published guidance in November 2023 for CVE-2023-4966, describing it as a buffer overflow that can disclose sensitive information, including session authentication tokens, on affected Gateway or AAA virtual servers. The guidance noted that stolen tokens could enable session hijacking.
MBSD-SOC observed that detections of exploitation attempts against CVE-2023-4966 increased after the start of November 2023. In its November data, many attack sources were attributed to Germany, followed by Russia, China, Japan, and the United States.
MBSD-SOC reported its first detection of attacks targeting CVE-2023-4966. The observed exploit traffic included a GET request to /oauth/idp/.well-known/openid-configuration with an unusually long Host header intended to obtain a session cookie.
CVE-2023-4966, affecting Citrix NetScaler ADC and NetScaler Gateway, was publicly disclosed. The flaw can enable authentication bypass and theft of sensitive information, including session-related data.
Kroll described a case in which the PLAY ransomware group used Citrix Bleed to gain access to a professional services firm. After initial access, Kroll observed four days of attacker activity including reconnaissance of domain accounts, trusted domains, permission groups, and remote systems.
NetScaler published investigation recommendations related to CVE-2023-4966. The publication marked a vendor response focused on helping customers investigate potential compromise.
Citrix released fixed NetScaler versions for CVE-2023-4966, including updates for supported ADC and Gateway branches while noting unsupported 12.1 versions were also affected. The update addressed the critical flaw later widely referred to as Citrix Bleed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
kroll.com
Open sourcembsd.jp
Open sourcenetscaler.com
Open sourcenetscaler.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.